From: Udhay Shankar N (firstname.lastname@example.org)
Date: Sat Feb 10 2001 - 01:07:49 PST
[resending since kragen.dnaco.net is down]
*xentinc.com* ? Rohit, you been doing something we should know(now) about ? :)
On Wed, 7 Feb 2001 14:50:52 -0000, in comp.security.misc "Dave Korn"
>email@example.com wrote in message <firstname.lastname@example.org>...
>>Below is an email header that was attached to some SPAM someone in my
>>network received. Maybe I'm reading it wrong, but it looks like the
>>email came from xentinc.com. However, everything I've seached (whois,
>>etc) says that xentinc.com does not exist. Am I missing something?
>>The hostnames and IP's have obviously been changed.
>>Received: from internal.smtp.com ([18.104.22.168]) by ex1.acs.xxx.com with
>>SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13)
>> id 1DZTSJ7A; Fri, 2 Feb 2001 13:31:20 -0500
>>Received: from internal.gtwy.xxx.com (internal.gtwy.xxx.com [22.214.171.124])
>> by internal.smtp.com (8.9.3/8.8.7) with SMTP id NAA18216
>> for <email@example.com>; Fri, 2 Feb 2001 13:34:49 -0500
> OK, these two hops are inside your corporate network, right.
>>Received: from unknown (xentinc.com) by external.smtp.com with SMTP id
>> (InterLock SMTP Gateway 4.2 for <firstname.lastname@example.org>);
>> Fri, 2 Feb 2001 13:33:46 -0500
> Well, you're fucked there. Your internal gateway keeps track of the HELO
>command sent by the spammer, which is almost certainly forged, but didn't
>bother logging the IP they connected from. This is worse than useless. You
>have no way whatsoever of tracing this spammer because your machine
>discarded the one vital piece of information that could have tracked them.
>>Subject: 24 HOUR LIVE F*CKING IN YOUR BROWSER wKgTUFh
> That sounds a bit cramped. Remember to maximize the window before you try
>They laughed at Galileo. They laughed at Copernicus. They laughed at
>Columbus. But remember, they also laughed at Bozo the Clown.
-- ((Udhay Shankar N)) ((udhay @ pobox.com)) ((www.digeratus.com)) God is silent. Now if we can only get Man to shut up.
This archive was generated by hypermail 2b29 : Mon Feb 12 2001 - 12:45:43 PST